AWS amazondynamodb: Add FGAC limitations for Vector Search operations
Summary
Documented that FGAC condition keys aren't supported in SearchVectors requests, requiring separate IAM statements.
Security assessment
Added guidance to prevent accidental access denial by clarifying IAM policy requirements for vector search operations, improving security configuration accuracy.
Evidence
+Because these condition keys are not present in the `SearchVectors` request context, a policy statement whose condition references one of them does not match a `SearchVectors` request, and DynamoDB denies access rather than granting it.
Diff
diff --git a/amazondynamodb/latest/developerguide/VectorSearch.Security.md b/amazondynamodb/latest/developerguide/VectorSearch.Security.md index 66ba38c2b..bd20c22c3 100644 --- a//amazondynamodb/latest/developerguide/VectorSearch.Security.md +++ b//amazondynamodb/latest/developerguide/VectorSearch.Security.md @@ -23,0 +24,4 @@ You can't use Amazon DynamoDB fine-grained access control (FGAC) with the `Searc +Because these condition keys are not present in the `SearchVectors` request context, a policy statement whose condition references one of them does not match a `SearchVectors` request, and DynamoDB denies access rather than granting it. Do not add `dynamodb:SearchVectors` to a statement that carries an FGAC condition. Grant `dynamodb:SearchVectors` in its own statement, scoped by the index resource ARN and with no `dynamodb:` FGAC conditions attached. + +If your existing policies scope Amazon DynamoDB access with `dynamodb:LeadingKeys`, `dynamodb:Attributes`, or `dynamodb:Select`, adding vector search means adding a separate statement rather than extending an existing one. +